Skip to content
Trust by design

Security at Laya

Laya holds real work — native boards, docs, and synced mirrors of the Jira, Azure DevOps, monday.com, GitHub and GitLab boards you connect. This page explains, in plain words, what we store, how it is protected, and how you take access away again — from either side.

Credentials encrypted at rest (AES-256-GCM)Encryption in transit on all trafficPasskey & authenticator 2FAMirrors deleted on disconnectNever used to train AI models
Where your data lives

Two kinds of data, one honest rule each.

Laya is deliberate about which tool is the system of record — and about the fact that connecting a board creates a real, durable copy, not a vague “cache”.

Native boards, docs and items

Work you create directly in Laya lives with us as your system of record. It is encrypted at rest, kept for as long as your account exists — nothing is auto-purged on a schedule — and it is yours to export at any time.

Connected (mirrored) boards

When you connect a board from Jira, Azure DevOps, monday.com, GitHub or GitLab, Laya imports and keeps a durable, synced copy of each item’s core fields — title, status, assignees, dates and links. Comments on connected boards are read live from the source tool through its own API rather than warehoused. Your provider stays the system of record, and when you disconnect a board Laya deletes its mirror of it.

Laya is operated from the United Kingdom by Laya.net and hosted on Amazon Web Services in the United States (us-east-1), with data processed under Standard Contractual Clauses and the UK IDTA. The full sub-processor list is published in the Laya privacy policy; the practical detail lives in How Laya protects your data.

Encryption

Credentials are encrypted, then never shown again.

At rest

Every credential for a connected tool — OAuth tokens, API tokens and keys — is encrypted at rest with AES-256-GCM, as are webhook signing secrets. Once saved, a credential is never returned by the API and never displayed in the app again.

In transit

All traffic is encrypted in transit, and the site ships strict browser protections: a Content-Security-Policy, HSTS, clickjacking protection (frame-ancestors denied) and a locked-down Permissions-Policy.

Passwords

Your Laya password is hashed, never stored in plain text, and must be at least 12 characters — enforced on the server, not just in the form.

Scoped access

OAuth and API tokens, in plain words.

Laya only ever acts with credentials you explicitly grant or create — it has no more access than the account or token you gave it, and it uses that access for one job: mirroring the boards you choose and pushing back the edits you make in Laya. Boards you have not connected are never touched.

How each tool connects to Laya and how you revoke access
ToolHow it connectsHow you revoke it
JiraOAuth (sign in with Atlassian), an API token, or the installed Laya Board for Jira appDisconnect in Laya, remove Laya from your Atlassian account’s authorised apps, or uninstall the app from the site
Azure DevOpsMicrosoft Entra OAuth, or a personal access token (PAT)Disconnect in Laya, revoke the PAT in Azure DevOps, or remove Laya’s authorisation from your Microsoft account
monday.comAn API tokenDisconnect in Laya, or regenerate / revoke the token in your monday.com account settings
GitHubA personal access token, or GitHub OAuth where it is configuredDisconnect in Laya, delete the token in GitHub developer settings, or revoke Laya’s OAuth authorisation
GitLabA personal access token, or GitLab OAuth where it is configuredDisconnect in Laya, revoke the token in GitLab, or revoke Laya’s OAuth authorisation from your applications

Connecting or disconnecting a tool is restricted to the workspace Owner and Admin roles, and disconnecting deletes the mirror along with the connection. The full breakdown — including what each grant is used for — is in Provider permissions and scopes and Disconnecting safely: what stays and what goes.

Your account

Sign-in security you control.

Ways in

Email and password, single-use magic links that expire after 10 minutes, or sign-in with Atlassian, Azure DevOps, Google, Microsoft or Slack. Sign-in and account routes are rate-limited against brute force. Every method is covered in Sign-in methods.

Two-factor authentication

Opt-in 2FA with passkeys — Face ID, Touch ID, Windows Hello or a security key — as the primary factor, an authenticator app as the fallback, and single-use recovery codes. Once it is on, the second factor is asked for on every route in, including magic links and social sign-in. Set it up with the two-factor authentication guide.

Sessions you can end instantly

Laya keeps you signed in rather than logging you out on a timer — safe because every request is checked server-side, so signing a session out from the Active sessions list kills it immediately, whatever the token’s age. Details in Sessions and account security.

Sharing

Share links stay private by default.

Public links for boards, docs and roadmaps are secret-token URLs — the token in the link is the only credential, so the link itself is the key.

  • Public views are read-only and rate-limited per IP.
  • Board shares let the owner choose which columns and card fields are visible, and whether viewers can open a read-only detail view.
  • Links can be revoked at any time — a revoked link shows an error, not content.
  • Share URLs are excluded from search engines: they are disallowed for crawlers and never listed in Laya’s sitemap.

See Sharing boards publicly for the controls in detail.

Commitments

What Laya never does.

We do not sell your data, and we do not use your content to train AI models — where AI features are available, the provider receives only the content you choose to run them on. Analytics run on the marketing site only, only after you accept them, and a Global Privacy Control or Do Not Track signal from your browser stops them loading at all. We act on your instruction and never repurpose your content.

On certifications, we would rather be straight with you: Laya does not yet hold formal certifications. SOC 2 and a signable DPA are coming, and GDPR-readiness work is in progress.
Report a security concern

Found a vulnerability, or seen activity on your account you do not recognise? Email support@laya.net with “Security report” in the subject line and steps to reproduce — and please never include passwords, tokens or recovery codes in the email.

Privacy requests, including data erasure, go to privacy@laya.net and are answered within one month. The formal terms live in the privacy policy and terms of service.

Try Laya with your own guardrails on.

Free during early access. Connect a board with a scoped grant, mirror it, and disconnect whenever you like — the mirror goes with it.

Create a free accountBrowse the security guides